Cloud Security Podcast

Join your hosts, Anton Chuvakin and Timothy Peacock, as they talk with industry experts about some of the most interesting areas of cloud security. If you like having threat models questioned and a few bad puns, please tune in!

cloud-security-podcast_high_res.png

Episode list

#99
November 28, 2022

EP99 Google Workspace Security: from Threats to Zero Trust

Guests:

  • Nikhil Sinha, Group Product Manager, Workspace Security
  • Kelly Anderson, Product Marketing Manager, Workspace Security
23:27

Topics covered:

  • We are talking about Google Workspace security today. What kinds of threats do we have to care about here?
  • Are there compliance-related motivations for security here too? Is compliance in the cloud changing?
  • How’s adoption of hardware keys for MFA going for your users, and how are you helping them? 
  • Is phishing finally solved because of that? 
  • Can you explain why hardware security FIDO/WebAuthn is such a step function compared to, say, RSA number generator tokens? 
  • Have there been assumptions in the Workspace security model we had to change because of WFH? And what changes with RTO and permanent hybrid?
#98
November 21, 2022

EP98 How to Cloud IR or Why Attackers Become Cloud Native Faster?

Guests:

27:27

Topics covered:

  • Let’s talk about security incident response in the cloud. Back in 2013 when I [Anton] first touched on this, the #1 challenge was getting the data to investigate as cloud providers had few logs available. What are the top 2022 cloud incident response challenges?
  • Does cloud change the definition of a security incident? Is “exposed storage bucket” an incident? Is vulnerability an incident in the cloud?
  • What should I have in my incident response plans for the cloud? Should I have a separate cloud IR plan?
  • What is our advice on running incident response jointly with a CSP like us?
  • How would 3rd party firms (like, well, Mandiant) work with a client and a CSP during an investigation?
  • We all read the Threat Horizons reports, but can you remind us of the common causes for cloud incidents we observed recently? What goals do the attackers typically pursue there?
#97
November 17, 2022

Special: Coordinated Release of Detection Rules for CobaltStike Abuse

Guest:

23:23

Topics covered:

  • Could you tell us a bit about your background and how you ended up here at Google? Also, tell us about your team here?
  • We're very excited about the release of the CobaltStrike rules. Could you share more about what they are looking for and second why this is so valuable?
  • How did CobaltStrike come to be so widely used by bad guys?
  • When you were doing this research what was the most surprising thing you uncovered?
  • Could you tell us about the coordinated disclosure aspects of this work?
  • In the past you've contributed research to our Threat Horizons reports, could you tell us about that?
#96
November 14, 2022

EP96 Cloud Security Observability for Detection and Response

Guest:

  • Jeff Bollinger,  Director of Incident Response and Detection Engineering @ Linkedin 
25:25

Topics covered:

  • Observability sounds cool (please define it for us BTW), but relating it to security has been “hand-wavy” at best. What is your opinion on the relevance of observability data for security use cases? What use cases are those, apart from saving the data for IR just in case?
  • How can we best approach observability in the cloud, particularly around network communications, so that we improve security as a result?
  • Are there other areas of cloud where observability might be more relevant? Does the massive shift to TLS 1.3 impact this?
  • If the Internet is shifting towards an end-user/device centric model with everything as a service (SaaS), how does security monitoring even work anymore? 
  • Does it mean the end of both endpoint and network eras and the arrival of the application security monitoring era?
  • Can we do deep monitoring of complex applications and app clusters for abuse or should we just focus on identity and profiling?
#95
November 7, 2022

EP95 Cloud Security Talks Panel: Cloud Threats and Incidents

Guests:

  • Alijca Cade, Director, Financial Services, Office of the CISO, Google Cloud
  • Ken Westin, Director, Security Strategy, Cybereason
  • Robert Wallace, Senior Director, Mandiant, now Google Cloud
27:23

Topics covered:

  • How are cloud environments attacked and compromised today? Is it still about the configuration mistakes?
  • Do cryptominers represent a serious threat now that they are often mentioned as the most common threat in the cloud?
  • Let’s look at another popular threat - ransomware or, broadly, RansomOps. Based on your research, what can we say about its likely future, especially in the cloud?
  • Are we getting better with detection in the cloud and are we doing it fast enough?
  • Is cloud security a misnomer? Attackers are out to get into an organization, and cloud or on-premise matters less here, right? What does it say about the interdependence of security, on and off cloud?
#94
October 31, 2022

EP94 Meet Cloud Security Acronyms with Anna Belak

Guest:

27:27

Topics covered:

  • Analysts (and vendors) coined a log of “C-something acronyms” for cloud security, and two of the people on this episode were directly involved in some of them. What do you make of all the cloud security acronym proliferation?
  • What is CSPM? What gets better when you deploy it?
  • What is CWPP? Does anything get better when you deploy it?
  • What is CNAPP? What gets better when you deploy it?
  • What is CIEM, Anton’s least fave acronym?
  • Now, what about CDR? 
#93
October 24, 2022

EP93 CISO Walks Into the Cloud: Frustrations, Successes, Lessons ... And Is My Data Secure?

Guest:

  • Alicja Cade, Director for Financial Services, Office of the CISO, Google Cloud 
28:30

Topics covered:

  • We are talking about your journey as a CISO migrating to the cloud. Could you give us the overview of …
    • What triggered your organization's migration to the cloud? When did you and the security team get brought in?
    • Did you take going to the cloud as an opportunity to change things beyond the tools you were using? 
  • As you got going into the cloud, what was the hardest part for your organization?
  • If that was hardest, what was most surprising? Good surprise and bad surprise?
  • How did you design security controls for the cloud?
  • How do you validate and verify security controls in the cloud?
  • How did you keep both security practitioners and the rest of your IT teams from lift-and-shift thinking?
  • Did your data security practice change?
  • Having covered all that tactical terrain, one final strategic question: is moving to the cloud a net risk reduction? Can it be?
#92
October 21, 2022

Special: Sharing The Mic In Cyber with STMIC Hosts Lauren and Christina: Representation, Psychological Safety, Security

Guests:

23:23

Topics covered:

  • We are so excited to have you on the show today talking about your awesome effort, Share The Mic in Cyber. I love that we are Sharing our Mic with you today. Could you please introduce yourself to our listeners?
  • Let's talk about representation and what that means, and why it's especially relevant in cyber security? 
  • Psychological safety is super important for so many reasons, including  in cyber. Could you share a definition of what it is, and why it is important? 
  • Can we talk about how psychological safety and representation intersect? 
  • Let’s bring things back to talk about the #ShareTheMicInCyber / #STMIC project. Could you tell us about one of your favorite things that's come from the project?  Any surprises? Lessons? Plans? Futures?
  • How can our listeners help with #ShareTheMicInCyber? Where to learn more?
#91
October 17, 2022

EP91 “Hacking Google”, Op Aurora and Insider Threat at Google

Guest:

  • Mike Sinno, Security Engineering Director, Detection and Response  @ Google
29:29

Topics covered:

  • You recently were featured in “Hacking Google” videos, can you share a bit about this effort and what role you played?
  • How long have you been at Google? What were you doing before, if you can remember after all your time here? What brought you to Google?
  • We hear you now focus on insider threats. Insider threat is back in the news, do you find this surprising?
  • A classic insider question is about “malicious vs well-meaning insiders" and which type is a bigger risk. What is your take here?
  • Trust is the most important thing when people think about Google, we protect their correspondence, their photos, their private thoughts they search for. What role does detection and response play in protecting user trust?
  • One fun thing about working at Google is our tech stack. Your team uses one of our favorite tools in the D&R org! Can you tell us about BrainAuth and how it finds useful things?
  • We talked about Google D&R (ep 17 and ep 75) and the role of automation came up many times. And automation is a key topic for a lot of our cloud customers. What do you automate in your domain of D&R?
#90
October 13, 2022

Next Special - Google Cybersecurity Action Team: One Year Later!

Guest:

29:29

Topics covered:

  • Google Cybersecurity Action Team is your brainchild and it is 1 year old, what comes to mind first when we reflect on this anniversary?
  • The team is primarily about helping clients with security, what did we learn doing this for a year?
  • What challenges have we (Google Cybersecurity Action Team) faced in our first year?
  • We released 4 Threat Horizons reports this year, what is the future for this research here?
  • We often hear that in the cloud we need to move away from products towards solutions, how does that work in security?
  • Your famous 8 megatrends post is several months old - any new thoughts or changes coming to this concept?
  • Recently you had a very interesting blog “Crucial Questions from CISOs and Security Teams”, with a list of questions, can you share some of your thinking here?